• News/
  • https://www.bleepingcomputer.com/news/security/trend-micro-warns-of-endpoint-protection-zero-day-exploited-in-attacks/

Trend Micro warns of Apex One zero-day exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Aug 6, 2025
·
Updated

Trend Micro has warned customers to immediately secure their systems against an actively exploited remote code execution vulnerability in its Apex One endpoint security platform. Apex One is an endpoint security platform designed to automatically detect and respond to threats, including malicious tools, malware, and vulnerabilities. This critical security flaw (tracked as CVE-2025-54948 and CVE-2025-54987 depending on the CPU architecture) is due to a command injection weakness in the Apex One Management Console (on-premise) that enables pre-authenticated attackers to execute arbitrary code remotely on systems running unpatched software. Trend Micro has yet to issue security updates to patch this actively exploited vulnerability, but it has released a mitigation tool that provides short-term mitigation against exploitation attempts. The Japanese CERT also issued an alert regarding the active exploitation of the two flaws, urging users to mitigate them as soon as possible. "While it will fully protect against known exploits, it will disable the ability for administrators to utilize the Remote Install Agent function to deploy agents from the Trend Micro Apex One Management Console," the company explained in a Tuesday advisory. "Trend Micro has observed as least one instance of an attempt to actively exploit one of these vulnerabilities in the wild." The company said it will release a patch around the middle of August 2025, which will also restore the Remote Install Agent funct...

Read full article

Affected Software

1 affected component
Trend Micro Apex One

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a zero-day vulnerability in Trend Micro's Apex One endpoint security platform that is currently being exploited in attacks.

2

What security implications are discussed?

The article highlights the risk of remote code execution due to the zero-day vulnerability, which could allow attackers to gain control of affected systems.

3

What products or software are affected?

The affected software mentioned in the article is Trend Micro Apex One.

4

What actions should users take in response to this vulnerability?

Users are urged to immediately secure their systems by applying the necessary updates and patches provided by Trend Micro.

5

Is there any indication of when this vulnerability was discovered?

The article does not specify when the zero-day vulnerability was discovered, but it emphasizes its active exploitation in the wild.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203